June 29, 2026

A Dropdown Value Is Still User Input: SQL Injection in WooCommerce’s Most Popular Order Export…

How a two-value dropdown toggle became a read-any-table SQL injection in a plugin on up to 500,000 stores

By Yaswanthrs

5 min read